Secure local vault for API keys, passwords, tokens, SSH keys, notes, JSON, .env files, and any other sensitive text.
Vault is a desktop-first, zero-cloud secret manager. Your data is encrypted locally before it is written to SQLite, and the master password is never stored. There is no account, telemetry, sync service, or network dependency.
- Store API keys, secret keys, access tokens, passwords, SSH private keys, recovery codes, license keys, environment variables, secure notes, plain text, JSON, and
.envconfiguration. - Search, filter, tag, favorite, copy, reveal, edit, and delete entries from a focused desktop interface.
- Export the entire vault to a password-protected
.vaultbackup and import it on another device. - Auto-locks after five minutes of inactivity and clears copied secrets from the clipboard after 30 seconds.
- Checks for signed updates in-app and lets you download, install, and restart from one click.
- Cross-platform Tauri shell with a Rust security boundary and a React + TypeScript UI.
Vault uses application-layer encryption so the SQLite database contains encrypted payloads rather than readable secrets:
| Layer | Implementation |
|---|---|
| Key derivation | Argon2id, 64 MiB memory, 3 iterations, 16-byte random salt |
| Item encryption | AES-256-GCM with a fresh 12-byte nonce per item |
| Key lifetime | Master key is held only in memory while the vault is unlocked |
| Database | Local SQLite with WAL and synchronous writes enabled |
| Export | Separate AES-256-GCM backup key derived from an export password |
| Network | CSP and application design keep the vault offline |
Security note: Vault is designed for local use. Keep your master password and backup password safe; they cannot be recovered by the application.
- Node.js 20 or newer
- Rust stable and Cargo
- Tauri prerequisites for your operating system (official guide)
git clone https://github.com/codeverta/vault.codeverta.com.git
cd vault.codeverta.com
npm install
npm run tauri devOn first launch, create a master password with at least 10 characters. The vault database is created in the operating system's application-data directory.
Download the latest installer from the GitHub Releases page. Vault release builds are produced for:
| Platform | Artifact |
|---|---|
| macOS Apple Silicon | .dmg and .app.tar.gz |
| Linux x64 | .AppImage and .deb |
| Windows x64 | .msi and .exe |
npm run tauri buildBundled installers are written to src-tauri/target/release/bundle/. The GitHub release workflow builds macOS, Linux, and Windows artifacts in parallel.
npm run check # TypeScript
npm run build # Vite production bundlecargo check --manifest-path src-tauri/Cargo.toml
cargo test --manifest-path src-tauri/Cargo.toml
cargo clippy --manifest-path src-tauri/Cargo.toml --all-targets -- -D warningsFrom this existing workspace, npm run release:local builds the current platform and uploads the installers to GitHub Releases. To build macOS, Linux, and Windows in GitHub Actions without downloading the repository yourself, run npm run release:ci.
See the release guide for signing setup and the complete workflow.
- Open Settings → Export & import.
- Choose a dedicated backup password and export a
.vaultfile. - Copy the file to the new device through your preferred secure channel.
- Create or unlock Vault on the new device, then import the backup with its backup password.
The backup password is separate from the master password. Vault never uploads or syncs this file.
When a newer signed release is available, Vault shows an Update button in the sidebar. Click it once to download, verify, install, and restart the application. No manual binary download is needed. Updates are verified against the public key bundled in the application.
src/ React + TypeScript interface
src-tauri/src/ Rust commands, encryption, and SQLite storage
src-tauri/icons/ Application icon assets
.github/workflows/ Continuous integration checks
docs/ Developer and release documentation
Bug reports and pull requests are welcome. Start with the developer documentation and read CONTRIBUTING.md before opening a change. The release guide covers versioning and publishing. Never include real credentials, tokens, private keys, or .vault backups in an issue or pull request.
For security issues, please follow SECURITY.md rather than opening a public issue.
Vault is released under the MIT License.
◆ Codeverta · Vault · 2026 ◆